The email arrived on a Thursday afternoon, the busiest day at a nine-person design studio. It came from their regular printing supplier, referenced a real project by name, and attached an invoice for $8,400. The only new detail: updated bank account information, “as we’ve switched banks.”
The bookkeeper paid it. Everything looked normal, the amount was believable, and the vendor was one they used every month. Three weeks later the real supplier called asking where their payment was. This is a composite of a scam that plays out the same way in small businesses every single day.
Key takeaways
- Invoice scams work by impersonating a real vendor you already trust and quietly changing the bank details.
- The email often references a real project, because the scammer has been reading your inbox.
- One phone call to a known number would have stopped an $8,400 loss.
- A simple rule (verify any change of payment details out loud) protects a small team completely.
How the scam actually worked
This was not a random blast. It was targeted, and it started earlier than anyone realized.

Weeks before, someone in the studio had clicked a phishing link and entered their email password on a fake login page. The scammer did not do anything loud with that access. They quietly read the mailbox, learning the studio’s vendors, projects, tone, and payment rhythm.
When they understood the pattern, they crafted an invoice that fit right in. Correct project name, believable amount, familiar supplier, and a plausible reason for the account change. The forgery worked because everything around the fake detail was true.
This pattern has a name: business email compromise. It is one of the costliest scams for small companies precisely because it does not look like a scam. There is no scary link and no obvious threat, just a routine-looking invoice.
The moment it could have been caught
There was a five-second window where the whole thing fell apart, and the studio walked right past it.
The email said the supplier had “switched banks.” That single sentence is the entire scam. A change of bank details is the one event that should always trigger a phone call to a number you already have, not the number in the email.
That supplier’s real phone number was already saved in the bookkeeper’s contacts. A 30-second call (“hey, did your bank details change?”) would have ended it. But it was Thursday, the studio was slammed, and the invoice looked routine, so the call never happened. Learning to pause on messages like this is the heart of the guide to spotting a phishing email before you click.
What it cost, beyond the $8,400
The obvious number was the wire transfer. The full bill was larger and messier.
| Cost | Rough amount | Notes |
|---|---|---|
| The fraudulent payment | $8,400 | Wired to the scammer’s account, mostly unrecoverable |
| Paying the real invoice again | $8,400 | The actual supplier still needed paying |
| Staff time on cleanup | $1,500+ | Days of calls to the bank, police, and vendor |
| Securing the breached email | $400 | IT help to reset accounts and check for other access |
| Trust with the supplier | Hard to price | An awkward, damaged relationship |
Because the money went out as a wire to a mule account, the bank recovered almost none of it. The studio effectively paid for that print job twice, plus the cleanup. For a nine-person business, that is a genuinely painful hit.
The three checks that would have stopped it
None of these are technical. Any small team can adopt all three this week.
1. Call to confirm any change of bank details
This is the golden rule. If an invoice, email, or message changes where money should go, verify it by calling a phone number you already had on file, never the number or link in the new message. Make it a hard, no-exceptions policy.
When I set this rule up for a friend’s small agency, we wrote it on a sticky note above the bookkeeper’s monitor: “New account number? Pick up the phone.” It has caught two attempts in two years. A sticky note beat an $8,400 loss.
2. Protect the email account with two-factor login
The whole scam started with a stolen email password. Two-factor authentication (a code from an app on top of the password) would have kept the scammer out of the mailbox, and without that inside knowledge the fake invoice never gets written.
3. Slow down on payment requests, especially on busy days
Scammers time their messages for your busiest moments on purpose, because that is when careful checks get skipped. A simple rule that all payments over a set amount get a second person’s eyes adds friction exactly where fraud tries to slip through.
How the recovery went
The studio reported the fraud to the bank immediately, but the money was already gone. They filed a report with the FBI’s Internet Crime Complaint Center, which tracks business email compromise, and reported it to the FTC. Fast reporting occasionally lets a bank freeze funds, so speed is worth it even when the odds are low.
Then they cleaned house: reset every email password, turned on two-factor across the company, and wrote the “call to confirm bank changes” rule into their process. The full sequence of what to do after fraud lands is laid out in the scam recovery steps guide, and the studio worked through nearly all of it.
They came out of it with sturdier habits, but at a steep tuition. The broader picture of how these cons operate lives in the beginner guide to spotting scams and phishing, which is worth sharing with anyone on your team who touches money.
Your afternoon checklist
- Write a firm rule: any change to vendor bank details gets confirmed by a phone call to a known number.
- Turn on two-factor authentication for every business email account today.
- Add a second-person approval step for payments over a set amount.
- Warn your bookkeeper that scam invoices arrive on the busiest days on purpose.
- Save your key vendors’ real phone numbers so you never rely on an email’s contact info.
- Teach the team that “switched banks” is a phrase that always triggers a verification call.
- If you get hit, report it fast to your bank and to ic3.gov, since speed can occasionally recover funds.
The studio was not careless; it was busy, and busy is where this scam lives. One phone call stood between a normal Thursday and paying an invoice twice, and that call is a habit any small team can build for free.